Executive brief
Open Babel, a widely used library for converting chemistry and molecular data files, contains a memory safety flaw when processing CSR format files. An attacker could provide a specially crafted file that, when opened by a user or processed by a service using this library, could lead to a program crash or unauthorized code execution. This affects various software tools and web services that rely on Open Babel for chemical data visualization and conversion.
Technical details
An out-of-bounds write vulnerability exists in Open Babel's CSR format parser within the `PadString` helper function. The root cause is a classic buffer overflow (CWE-120) where a title field longer than the fixed-size destination buffer is copied without adequate bounds checking. While the vulnerability is triggered locally by opening a malicious file, the impact is significant as Open Babel is often integrated into web-based molecular viewers and conversion services. Exploitation can lead to memory corruption and arbitrary code execution. The issue is fixed in version 3.2.0 by implementing proper buffer size checks and using safe memory copy operations.
Affected products
- Open Babel Open Babel <= 3.1.1
Timeline
- 2023-07-21: disclosed: Initial disclosure by Cisco Talos
- 2026-05-26: patched: Version 3.2.0 released with fix
- 2026-07-01: advisory: GitHub Advisory published
References
- https://github.com/openbabel/openbabel/security/advisories/GHSA-p594-7xw4-g76p
- https://github.com/openbabel/openbabel/commit/528c142f3ad1e3036fc464944f31a23a960cdc3f
- https://talosintelligence.com/vulnerability_reports/TALOS-2022-1667
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2022-1667
- https://api.github.com/repos/openbabel/openbabel/security-advisories/GHSA-p594-7xw4-g76p